Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
vamseeachanta Skill Github Actions 1 Security Best PracticesSub-skill of github-actions: 1. Security Best Practices (+3).
Audited -
vamseeachanta Skill Periodic Skill Ecosystem Housekeeping AuditMaintain a deterministic recurring skill ecosystem housekeeping audit covering skill content quality, grouping/taxonomy drift, size, waivers, baselines, and local-only GitHub payloads.
Audited -
vamseeachanta Skill Read Only Pre Implementation AuditSystematic cross-check workflow to validate assumptions before TDD coding begins
Audited -
vamseeachanta Skill Github Code Review Security IssueSub-skill of github-code-review: Security Issue (+1).
Audited -
vamseeachanta Skill Hidden Folder Audit Verify Hidden Folder StateSub-skill of hidden-folder-audit: Verify Hidden Folder State (+3).
Audited -
vamseeachanta Skill Audit Support Workpaper RequirementsSub-skill of audit-support: Workpaper Requirements (+2).
Audited -
thomasmoreai Skill Compliance Check Nordic AIRegulatory and legal compliance audit. Discovers which frameworks apply based on jurisdiction, industry, and data types, then checks the codebase against the applicable controls. EU-first (GDPR, NIS2, EU AI Act, DORA) with support for UK, US federal and state laws, sector-specific regimes (HIPAA, PCI-DSS, SOC 2, ISO 27001), and emerging AI regulation. Use when the user asks about GDPR, compliance, regulation, data protection law, audit readiness, invokes /compliance-check, or when the orchestrator delegates. Mode-aware and scope-tier-aware.
Audited -
thomasmoreai Skill Fachanwalt Sozialrecht Sgb Ii BescheidWorkflow-Skill zu fachanwalt sozialrecht sgb ii bescheid. Nutzt Normtext, Nutzerangaben und verifizierte Quellen; Rechtsprechung nur nach Live-Pruefung mit Gericht, Datum und Aktenzeichen.
Audited -
thomasmoreai Skill Prepare Inspection Readiness Pjt222Prepare an organisation for regulatory inspection by assessing readiness against agency-specific focus areas (FDA, EMA, MHRA). Covers warning letter and 483 theme analysis, mock inspection protocols, document bundle preparation, inspection logistics, and response template creation. Use when a regulatory inspection has been announced or is anticipated, when a periodic self-assessment is due, when new systems have been implemented since the last inspection, or after a significant audit finding that may attract regulatory attention.
Audited -
thomasmoreai Skill Generate Compliance Audit DocumentGenerate a formatted PDF compliance audit document with findings, risk ratings, remediation recommendations, and sign-off sections.
Audited -
thomasmoreai Bundle Screening Alert Adjudication Amir FadaviAdjudicates whether a hit generated by sanctions, PEP, or adverse-media screening is a true positive, false positive, or requires human escalation. Use whenever a user presents a screening alert, a name match against a watchlist (OFAC SDN, EU consolidated list, UK OFSI, UN list, PEP list, adverse media hit, etc.), or asks to clear a screening hit / reduce false positives / determine whether a flagged name is actually the listed party. Use even when the user describes the task casually — "is this person actually on the sanctions list", "did we get a real match", "clear this alert", "I have a hit on X" — these are all screening-adjudication tasks. Produces a deterministic determination with full audit trail (structured JSON + human-readable narrative). Designed for use by compliance analysts and screening systems.
-
vamseeachanta Skill Sparc Architecture Example 3 Security ArchitectureSub-skill of sparc-architecture: Example 3: Security Architecture (+1).
Audited -
vamseeachanta Skill Testing Production Example 4 Security ValidationSub-skill of testing-production: Example 4: Security Validation.
Audited -
vamseeachanta Skill Provider Session Ecosystem AuditAudit Codex/Codex/Hermes/Gemini session logs, normalize provider-specific quirks, and wire recurring exports/reporting for ongoing ecosystem health checks.
Audited -
vamseeachanta Skill Hidden Folder Audit SpecsarchiveSub-skill of hidden-folder-audit: specs/archive/ (+1).
Audited -
vamseeachanta Skill Multi Tool Architecture AssessmentSystematic comparison of competing tools/approaches before committing to a multi-account, multi-tool architecture. Uses parallel subagents for research, system-state audit, and data quality analysis. Produces a decision matrix with explicit trade-offs.
Audited -
vamseeachanta Skill Plan Exit Governance Drift HandoffWhen ending a session on an iterated plan draft, audit and document approval-state drift across GitHub labels, local approval markers, README status, and latest review verdicts.
Audited -
vamseeachanta Skill Provider Session Learning TransferRefresh provider session audit, identify post-audit/unassessed sessions, extract actionable learnings, and transfer them into repo notes and GitHub issues before a follow-up implementation session.
Audited -
vamseeachanta Skill Orcawave Orcaflex Readiness AuditAudit the real readiness of digitalmodel OrcaWave/OrcaFlex spec-driven workflows by reconciling workspace-hub issues, source/tests, semantic-equivalence boundaries, and wiki synthesis gaps.
Audited -
vamseeachanta Skill Audit Support OverviewSub-skill of audit-support: Overview (+3).
Audited -
vamseeachanta Skill Hidden Folder Audit Best PracticesSub-skill of hidden-folder-audit: Best Practices.
Audited -
vamseeachanta Skill Plan Review Approval Shortlist AuditAudit a status:plan-review queue to identify true approval candidates without being fooled by stale labels, conditional review summaries, or unresolved prerequisite blockers.
Audited -
ferroxlabs Bundle QA EngineerBecomes a senior QA engineer who designs comprehensive test strategies, writes automated tests, and builds quality assurance processes for software projects. Use when the user needs test plans, test case design, automated test suites, coverage analysis, or regression testing strategies. Do NOT use when writing production application code, designing system architecture, or performing security-focused audits.
37 -
ferroxlabs Bundle Soc AnalystSecurity operations center expertise covering SIEM query writing, alert triage workflows, incident investigation procedures, IOC analysis, threat hunting techniques, playbook design, log analysis patterns, Splunk and Elastic SIEM queries, alert fatigue reduction, escalation procedures, and shift handoff practices. Use when the user asks about soc analyst, soc analyst best practices, or needs guidance on soc analyst implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
37 -
ferroxlabs Bundle Annual ReviewRuns a structured annual review including achievement audit, theme identification, lesson extraction, and 12-month forward projection. Use when the user wants to reflect on the past year, identify patterns in their accomplishments and failures, extract lessons learned, or plan the year ahead. Do NOT use for business annual reviews or performance evaluations (use business HR skills), quarterly planning (use `quarterly-planning`), or single-goal assessment (use `smart-goal-builder` instead).
37 -
ferroxlabs Bundle Code ReviewerBecomes a senior code reviewer who evaluates pull requests and code changes for correctness, security, performance, and maintainability. Use when the user asks for code review, PR feedback, code quality assessment, or merge readiness evaluation. Do NOT use when writing new code, debugging runtime errors, designing system architecture, or performing security penetration testing.
37 -
ferroxlabs Bundle Content AuditCreates structured content audits with performance categorization, gap analysis, and prioritized action recommendations for existing content libraries. Use when the user wants to evaluate their existing content, audit blog posts or website pages, identify underperforming content, or plan content updates. Do NOT use for planning new content (use `editorial-calendar`), writing content briefs (use `content-brief`), or analyzing audience personas (use `audience-analysis`).
37 -
ferroxlabs Bundle Content BriefCreates writer-ready content briefs with audience definition, content angle, detailed outline, keyword targets, source suggestions, and tone guidance. Use when the user needs to brief a writer, plan a content piece before drafting, or create an assignment document for content creation. Do NOT use for editorial calendars (use `editorial-calendar`), content audits (use `content-audit`), or writing the actual content piece (use `blog-post-writing`).
37 -
ferroxlabs Bundle Move CleaningProvides room-by-room cleaning checklists for move-in and move-out scenarios with specific tasks, time estimates, and security deposit recovery strategies. Covers the difference between move-out cleaning standards and regular cleaning, landlord inspection expectations, and DIY vs. professional cleaning cost comparisons. Use when the user is moving out of a rental and wants to maximize their security deposit return, moving into a new home and wants to clean before unpacking, or needs to prepare a home for new tenants. Do NOT use for regular cleaning routines (use weekly-cleaning-schedule), deep cleaning outside of a move context (use deep-cleaning-checklist), or post-construction cleaning.
37 -
ferroxlabs Bundle Tenant RightsComprehensive guide to tenant rights including lease review, security deposit rules, habitability standards, repair procedures, eviction process, rent increases, lease breaking options, documentation practices, and fair housing basics. Use when the user asks about tenant rights, or needs help with comprehensive guide to tenant rights including lease review, security deposit rules, habitability standards, repair procedures, eviction process, rent increases, lease breaking options, documentation practices, and fair housing basics. Do NOT use when the request requires professional legal advice or falls outside the scope of tenant rights.
37 -
ferroxlabs Bundle Env File ManagerBest practices for managing env-config files - setup, secrets management, environment separation, dotenv configuration, and security patterns for development teams. Use when the user asks about env file manager, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of env file manager or requires a different specialized skill.
37 -
ferroxlabs Bundle Nginx ConfigurerNginx configuration. Reverse proxy setup, load balancing, SSL termination, caching headers, gzip compression, rate limiting, security headers, location block patterns, upstream configuration, performance tuning. Use when the user asks about nginx configurer, nginx configurer best practices, or needs guidance on nginx configurer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
37 -
ferroxlabs Bundle OAUTH SpecialistOAuth 2.0 and OpenID Connect implementation expertise covering Authorization Code with PKCE, Client Credentials flow, token management, scope design, consent flows, token introspection, revocation, JWT validation, provider integration patterns, and security considerations for building secure authentication and authorization systems. Use when the user asks about oauth specialist, oauth specialist best practices, or needs guidance on oauth specialist implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
37 -
ferroxlabs Bundle Security AuditorBecomes a principal security engineer who conducts comprehensive security audits of applications, APIs, and infrastructure using threat modeling and vulnerability analysis methodologies. Use when the user needs a security review, threat model, vulnerability assessment, or security architecture evaluation. Do NOT use when writing application code, configuring CI/CD pipelines, or performing routine code reviews without a security focus.
37 -
ferroxlabs Bundle Smart Home SetupPlans a smart home system covering device compatibility frameworks, hub versus hub-free architectures, network requirements, and privacy considerations. Produces a phased implementation plan with device categories, protocol selection, and network preparation steps. Use when the user asks about setting up smart home devices, choosing a smart home platform, connecting devices together, home automation planning, or smart home privacy and security. Do NOT use for specific device configuration or troubleshooting, home network infrastructure design (routers, switches, cabling), or commercial building automation systems.
37 -
ferroxlabs Bundle Start RetirementGuides the user through the complete retirement transition from savings assessment through lifestyle design, chaining retirement calculators, financial tracking, budgeting, insurance, estate planning, and career transition skills across multiple categories. Use when the user is planning to retire, preparing for retirement within 2 years, or evaluating whether they are financially ready to retire. Do NOT use for early retirement (FIRE) investment strategy, pension administration, or Social Security disability claims.
37
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include github-actions-1-security-best-practices, periodic-skill-ecosystem-housekeeping-audit, read-only-pre-implementation-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.